Description
A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without a terminator. This vulnerability leads to unbounded memory accumulation within the client's Java Virtual Machine (JVM) heap, causing an `OutOfMemoryError` and a denial of service (DoS) due to a process crash.
Published: 2026-09-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Memory Exhaustion
Action: Apply Patch
AI Analysis

Impact

This vulnerability occurs in Netty's SmtpResponseDecoder component, where an attacker can send an unbounded multi‑line SMTP response without a terminator. The decoder accumulates the data in the JVM heap, eventually causing an OutOfMemoryError and crashing the application. The result is a denial of service. The weakness maps to CWE‑1035.

Affected Systems

Products impacted are Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat Single Sign‑On 7, and the Red Hat build of Apache Camel for Spring Boot 4. No specific version numbers are listed, so any release incorporating the affected Netty library may be vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity flaw, and the EPSS score is 0.00325, indicating a very low but nonzero likelihood of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. A remote attacker who can act as a malicious or man‑in‑the‑middle SMTP server can craft a response that will trigger the memory leak. The attack requires network access to the SMTP client, making the risk significant for systems exposing SMTP services.

Generated by OpenCVE AI on September 19, 2026 at 18:12 UTC.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-pq4x-537v-r54q for fixed versions and remediation guidance.


OpenCVE Recommended Actions

  • Upgrade Netty to a version that includes the fix referenced by the GitHub advisory.
  • If upgrading is not immediately possible, apply the workaround provided in the advisory to limit the size of SMTP responses processed.
  • Disable or restrict unnecessary SMTP server communication to reduce exposure.
  • Monitor application logs for OutOfMemoryError exceptions and configure alerts for rapid response.

Generated by OpenCVE AI on September 19, 2026 at 18:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3
Redhat single Sign-on
Vendors & Products Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Redhat quay 3
Redhat single Sign-on

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory-exhaustion DoS A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without a terminator. This vulnerability leads to unbounded memory accumulation within the client's Java Virtual Machine (JVM) heap, causing an `OutOfMemoryError` and a denial of service (DoS) due to a process crash.
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Netty: netty-codec-smtp: io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dos Io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dos

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Fri, 18 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Unbounded multi-line response accumulation in SmtpResponseDecoder leads to memory-exhaustion DoS
Title Netty: netty-codec-smtp: io.netty/netty-codec-smtp: netty: unbounded multi-line response accumulation in smtpresponsedecoder leads to memory-exhaustion dos
First Time appeared Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
Weaknesses CWE-1035
CPEs cpe:/a:redhat:camel_spring_boot:4
cpe:/a:redhat:jboss_enterprise_application_platform:7
cpe:/a:redhat:jboss_fuse:7
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat
Redhat camel Spring Boot
Redhat jboss Enterprise Application Platform
Redhat jboss Fuse
Redhat red Hat Single Sign On
References

Subscriptions

Io.netty Netty-codec-http
Redhat Build Of Apache Camel For Spring Boot Camel Spring Boot Jboss Enterprise Application Platform Jboss Fuse Quay 3 Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-25T08:28:58.433Z

Reserved: 2026-09-18T09:56:54.043Z

Link: CVE-2026-93563

cve-icon Vulnrichment

Updated: 2026-09-18T19:07:49.243Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T11:17:21.773

Modified: 2026-09-25T09:17:07.417

Link: CVE-2026-93563

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T00:46:23Z

Links: CVE-2026-93563 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:48Z

Weaknesses